Release date: 2011-12-12
Updated on: 2011-12-13
Affected Systems:
Simon Tatham puttty 0.61
Simon Tatham puttty 0.60
Simon Tatham puttty 0.59
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51021
PuTTY is an implementation of PuTTYTelnet and SSH on Windows and Unix platforms, with an xterm terminal simulator.
PuTTY versions 0.59 to 0.61 do not delete the content entered by the user during the authentication process. The user's password is saved in the memory. After successful exploitation, attackers can obtain sensitive information.
<* Source: vendor
Link: http://www.chiark.greenend.org.uk /~ Sgtatam/putty/wishlist/password-not-wiped.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Simon Tatham
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.chiark.greenend.org.uk /~ Sgtatham/putty/